Vulnerability Details CVE-2026-41280
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
This issue affects Apache DolphinScheduler versions prior to 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 9.5%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2026-41280
-
cpe:2.3:a:apache:dolphinscheduler:1.0.0
-
cpe:2.3:a:apache:dolphinscheduler:1.0.1
-
cpe:2.3:a:apache:dolphinscheduler:1.0.2
-
cpe:2.3:a:apache:dolphinscheduler:1.0.3
-
cpe:2.3:a:apache:dolphinscheduler:1.0.4
-
cpe:2.3:a:apache:dolphinscheduler:1.0.5
-
cpe:2.3:a:apache:dolphinscheduler:1.1.0
-
cpe:2.3:a:apache:dolphinscheduler:1.2.0
-
cpe:2.3:a:apache:dolphinscheduler:1.2.1
-
cpe:2.3:a:apache:dolphinscheduler:1.3.0
-
cpe:2.3:a:apache:dolphinscheduler:1.3.1
-
cpe:2.3:a:apache:dolphinscheduler:1.3.2
-
cpe:2.3:a:apache:dolphinscheduler:1.3.3
-
cpe:2.3:a:apache:dolphinscheduler:1.3.4
-
cpe:2.3:a:apache:dolphinscheduler:1.3.6
-
cpe:2.3:a:apache:dolphinscheduler:1.3.8
-
cpe:2.3:a:apache:dolphinscheduler:1.3.9
-
cpe:2.3:a:apache:dolphinscheduler:2.0.0
-
cpe:2.3:a:apache:dolphinscheduler:2.0.1
-
cpe:2.3:a:apache:dolphinscheduler:2.0.2
-
cpe:2.3:a:apache:dolphinscheduler:2.0.3
-
cpe:2.3:a:apache:dolphinscheduler:2.0.4
-
cpe:2.3:a:apache:dolphinscheduler:2.0.5
-
cpe:2.3:a:apache:dolphinscheduler:2.0.6
-
cpe:2.3:a:apache:dolphinscheduler:2.0.7
-
cpe:2.3:a:apache:dolphinscheduler:2.0.8
-
cpe:2.3:a:apache:dolphinscheduler:2.0.9
-
cpe:2.3:a:apache:dolphinscheduler:3.0.0
-
cpe:2.3:a:apache:dolphinscheduler:3.0.1
-
cpe:2.3:a:apache:dolphinscheduler:3.0.2
-
cpe:2.3:a:apache:dolphinscheduler:3.0.3
-
cpe:2.3:a:apache:dolphinscheduler:3.0.4
-
cpe:2.3:a:apache:dolphinscheduler:3.0.5
-
cpe:2.3:a:apache:dolphinscheduler:3.0.6
-
cpe:2.3:a:apache:dolphinscheduler:3.1.0
-
cpe:2.3:a:apache:dolphinscheduler:3.1.1
-
cpe:2.3:a:apache:dolphinscheduler:3.1.2
-
cpe:2.3:a:apache:dolphinscheduler:3.1.3
-
cpe:2.3:a:apache:dolphinscheduler:3.1.4
-
cpe:2.3:a:apache:dolphinscheduler:3.1.5
-
cpe:2.3:a:apache:dolphinscheduler:3.1.6
-
cpe:2.3:a:apache:dolphinscheduler:3.1.7
-
cpe:2.3:a:apache:dolphinscheduler:3.1.8
-
cpe:2.3:a:apache:dolphinscheduler:3.1.9
-
cpe:2.3:a:apache:dolphinscheduler:3.2.0
-
cpe:2.3:a:apache:dolphinscheduler:3.2.1
-
cpe:2.3:a:apache:dolphinscheduler:3.2.2
-
cpe:2.3:a:apache:dolphinscheduler:3.3.0
-
cpe:2.3:a:apache:dolphinscheduler:3.3.1
-
cpe:2.3:a:apache:dolphinscheduler:3.3.2
-
cpe:2.3:a:apache:dolphinscheduler:3.4.0
-
cpe:2.3:a:apache:dolphinscheduler:3.4.1